<?php
	include ('../inicio/conectarse.php');
	session_start();
	//Function to sanitize values received from the form. Prevents SQL injection
	function clean($str) {
		$str = @trim($str);
		if(get_magic_quotes_gpc()) {
			$str = stripslashes($str);
		}
		return mysql_real_escape_string($str);
	}
	
	//Sanitize the POST values
	$login = clean($_POST['login']);
	$password = clean($_POST['password']);

	
	//Create query	
	$qry="SELECT id_usuario, nombre, apellido, id_tipo_usuario FROM usuarios WHERE mail='$login' AND password='".md5($_POST['password'])."'";
	$result=mysql_query($qry);
	
	//Check whether the query was successful or not
	if($result) {
		if(mysql_num_rows($result) == 1) {
			//Login Successful
			session_regenerate_id();
			$member = mysql_fetch_array($result, MYSQL_ASSOC);
			$_SESSION['SESS_MEMBER_ID'] = $member['id_usuario'];
			$_SESSION['SESS_FIRST_NAME'] = $member['nombre'];
			$_SESSION['SESS_LAST_NAME'] = $member['apellido'];
			$_SESSION['SESS_TIPO_ID'] = $member['id_tipo_usuario'];
			session_write_close();
			//header("location: member-index.php");
			if($_SESSION['SESS_MEMBER_ID'] = 1){
				header("location: ../admin/index.php");
			}else{
				header("location: ../user/index.php");
			}	
			exit();
		}else {
			//Login failed
			$errLogin = 'Fallo en el Login';
			$_SESSION['ERRMSG_ARR'] = $errLogin;
			header("location: ../inicio/index.php");
			exit();
		}
	}else {
		die("Query failed");
	}
?>